Impact
A vulnerability exists in the Discovery Framework component of Oracle Enterprise Manager Base Platform, resulting in the possibility for an unauthenticated attacker with network access over HTTPS to create, delete, modify, or read critical data, and to cause a partial denial of service. The weakness is classified as CWE‑306, an authentication bypass that permits unauthorized operations. The vulnerability has a CVSS 3.1 Base Score of 7.0, indicating moderate to high impact on confidentiality, integrity, and availability.
Affected Systems
Affected products are Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. The issue impacts the Discovery Framework module within these releases and has been documented by Oracle in its July 2026 CPU advisory.
Risk and Exploitability
The EPSS score is less than 1 %, and the vulnerability is not listed in the CISA KEV catalog, signifying a low but nonzero likelihood of exploitation. The vector is inferred to be over the network via HTTPS; the advisory notes that the exploit is difficult. Nonetheless, the potential for significant data manipulation and service disruption warrants immediate attention.
OpenCVE Enrichment